Cyber Insurance Evidence Checklist
Map insurer questions to the documentation they expect
Cyber insurance questionnaires typically ask 30-50 yes/no questions about your security posture. Underwriters weigh your answers against industry benchmarks and peer data.
This checklist maps the most common questions to the evidence underwriters expect to see. Use it to identify documentation gaps before submitting your application.
1. Multi-Factor Authentication (MFA)
Insurer Question:
"Do you require MFA for all remote access and privileged accounts?"
Evidence Required:
- Screenshot of MFA configuration in remote access tools (VPN, RDP gateways, cloud admin portals)
- Policy document requiring MFA for remote/privileged access
- List of covered systems: email (Microsoft 365, Google Workspace), VPN, admin consoles, cloud platforms
- Enforcement status (100% coverage vs. partial rollout)
Red Flag: "We have MFA but it's optional" or "MFA on email only" typically results in higher premiums or denial.
2. Data Backup & Recovery
Insurer Question:
"Do you maintain offline/immutable backups and test recovery quarterly?"
Evidence Required:
- Backup schedule (daily, weekly) and retention policy
- Offline/air-gapped backup confirmation (disconnected from network or immutable cloud storage)
- Most recent recovery test report with date, systems tested, and success/failure outcomes
- Documented procedure for restore operations
Strong Signal: Quarterly tested restores with documented results show operational maturity underwriters value.
3. Endpoint Detection & Response (EDR)
Insurer Question:
"Do you deploy EDR or next-generation antivirus on all endpoints?"
Evidence Required:
- Name of EDR/NGAV solution (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, etc.)
- Deployment coverage percentage (target: 100% of workstations and servers)
- Screenshot of management console showing agent deployment status
- Policy requiring EDR on all corporate devices
Red Flag: Traditional antivirus alone (Symantec, McAfee legacy products) is typically insufficient. Insurers expect behavioral detection capabilities.
4. Email Security & Phishing Protection
Insurer Question:
"Do you use advanced email filtering and conduct phishing simulation training?"
Evidence Required:
- Email security solution name (Proofpoint, Mimecast, Microsoft Defender for Office 365, Barracuda)
- Features enabled: spam filtering, malware scanning, URL rewriting, attachment sandboxing
- Most recent phishing simulation results (date, click rate, reporting rate)
- Security awareness training completion percentage
Strong Signal: Regular phishing tests (quarterly) with documented improvement trends demonstrate active risk management.
5. Patch Management
Insurer Question:
"Do you apply critical patches within 30 days of release?"
Evidence Required:
- Documented patch management policy with timelines (critical: 7-30 days, high: 30-60 days)
- Patch management tool in use (WSUS, SCCM, automated cloud patching)
- Most recent patch compliance report showing percentage of systems up to date
- Process for emergency/out-of-band patching
Red Flag: Manual patching "as time allows" or unpatched systems older than 90 days signals elevated risk.
6. Incident Response Planning
Insurer Question:
"Do you have a written incident response plan and test it annually?"
Evidence Required:
- Written incident response plan (10-20 pages typical)
- Defined roles and escalation procedures
- Contact list for internal team and external resources (forensics, legal, breach coach)
- Most recent tabletop exercise or simulation report with date and participants
Strong Signal: Pre-negotiated retainers with incident response vendors demonstrate preparedness underwriters value.
7. Access Controls & Privilege Management
Insurer Question:
"Do you enforce least-privilege access and review permissions quarterly?"
Evidence Required:
- Access control policy requiring role-based permissions
- List of users with administrative privileges (should be minimal)
- Most recent access review report with date and findings
- Process for onboarding/offboarding (access granted day 1, revoked immediately upon termination)
Red Flag: "Everyone has admin rights" or no documented access reviews in the last year signals weak governance.
8. Network Security & Segmentation
Insurer Question:
"Do you segment your network and use next-generation firewalls?"
Evidence Required:
- Network diagram showing segmentation (guest, internal, server VLANs)
- Firewall make/model and version
- Security features enabled: IPS, application control, web filtering
- Policy restricting direct internet access from internal segments
Strong Signal: Segmented networks that isolate critical assets reduce blast radius underwriters care about.
9. Vendor Risk Management
Insurer Question:
"Do you assess third-party vendor security before contracting?"
Evidence Required:
- Vendor risk assessment policy
- List of critical vendors with access to your data or systems
- Sample vendor security questionnaire or due diligence checklist
- Contracts with security requirements and audit rights clauses
Red Flag: No vendor security evaluation process or inability to list critical third parties signals supply chain risk.
10. Security Awareness Training
Insurer Question:
"Do all employees complete annual security awareness training?"
Evidence Required:
- Training program name/vendor (KnowBe4, Proofpoint, internal)
- Topics covered: phishing, passwords, data handling, incident reporting
- Completion rate (target: 100% of employees)
- Most recent training campaign date and results
Strong Signal: 100% training completion within 30 days of hire plus annual refreshers demonstrate culture of security.
Critical Control Priority Matrix
Underwriters weight controls differently. Focus remediation here first:
Highest Impact (Address First):
- ✓ MFA on all remote access and privileged accounts
- ✓ Offline/immutable backups with quarterly tested restores
- ✓ EDR deployed on all endpoints (not legacy AV)
High Impact (Address Next):
- ✓ Email security with phishing simulation training
- ✓ Documented incident response plan with annual testing
- ✓ Patch management with <30 day critical patch SLA
Ready to Build Your Evidence Package?
We conduct framework-aligned assessments, identify critical gaps, implement required controls, and provide documentation underwriters expect to see. Typical timeline: 60-90 days from assessment to application-ready.
Note: Insurance requirements vary by carrier, coverage limits, and industry. This checklist represents common requirements across major cyber insurers as of 2026. Consult with your broker for carrier-specific expectations.
Last updated: September 2026